CVE-2025-50485: High severity Phpgurukul Online Course Registration vulnerability
Published Jul 28, 2025
·Updated
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.
Affected Software
2 affected components
Phpgurukul Online Course Registration
Phpgurukul Online Course Registration=3.1
Event History
Jul 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50485?
CVE-2025-50485 has a critical severity level due to its potential for session hijacking attacks.
2
How do I fix CVE-2025-50485?
To fix CVE-2025-50485, implement proper session invalidation techniques in the affected component /crm/change-password.php.
3
What are the potential impacts of CVE-2025-50485?
The potential impacts of CVE-2025-50485 include unauthorized access to user accounts through session hijacking.
4
Which software is affected by CVE-2025-50485?
CVE-2025-50485 affects PHPGurukul Online Course Registration version 3.1.
5
Is there a workaround for CVE-2025-50485?
Currently, the only reliable solution for CVE-2025-50485 is applying the necessary patch to ensure proper session management.